Identifying sources of memory
What happens if you are not the investigator on the scene when the digital evidence is collected in the RAM, and they do not collect volatile data? Is it possible to still access the RAM, despite having the system shut down? While you cannot analyze the RAM, it is possible to examine other sources containing the same data stored in the RAM. This option may not always be viable, depending on the specific set of circumstances surrounding the seizure of the digital evidence.
You need to know that there are potential additional sources containing the same or similar data in RAM. They are as follows:
- Hibernation file (hiberfil.sys): Hibernation is the process of powering down the computer while still maintaining the current state of the system. In Windows, the RAM is compressed and stored in a
hiberfil.sys
file. This will allow the system to power down completely, but when the system is reactivated, the contents of thehiberfil.sys
file will...